A network security prevention method based on cryptographic technology and a computer-readable storage medium

By building multiple password blocks and mobile spaces in the network and dynamically adjusting their locations, the problem of resisting malicious attacks in complex network environments is solved, and more efficient network security protection is achieved.

CN119835066BActive Publication Date: 2025-07-08HANGZHOU QIWEI ENTERPRISE MANAGEMENT PARTNERSHIP (LLP)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510035977.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-07-08
Estimated Expiration
2045-01-09

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively resist malicious attacks in complex network environments, and it is difficult to fully defend against supercomputer attacks simply by increasing password complexity, and network system security is insufficient.

Method used

Build multiple password blocks, distributed in mobile spaces in different physical locations and logical areas, enhance network security through dynamic mobile policies, use network topology and mobile space to cover the entire network, and dynamically adjust the location of password blocks to improve security.

Benefits of technology

By dynamically moving password blocks and mobile space, the comprehensive coverage and security of the network are enhanced, the difficulty of attackers to obtain all password blocks is reduced, and the protection capabilities of the network system are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119835066B_ABST
    Figure CN119835066B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, and particularly relates to a network security prevention method and a computer-readable storage medium based on cryptographic technology. The method includes: Step 1: Obtain the network topology structure and set the network security prevention boundary; Step 2: Construct a cryptographic block, where the cryptographic block includes a unique identifier, data content, and metadata; Step 3: Construct multiple mobile spaces, distribute the multiple mobile spaces at different physical locations and logical regions of the network, cover the entire network through the multiple mobile spaces, and each mobile space covers multiple network connection nodes; Step 4: Put multiple cryptographic blocks into the mobile spaces, and the number of the cryptographic blocks is not less than the number of network nodes; Step 5: According to a preset movement strategy, control the dynamic movement of the cryptographic blocks between the respective mobile spaces and control the dynamic movement of the respective mobile spaces within the network security prevention boundary; the movement strategy is triggered based on network events and / or triggered based on time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security prevention method based on cryptographic technology and a computer-readable storage medium. Background Art

[0002] Existing technologies use cryptographic technology for identity authentication and access control, which is the basis for ensuring that only authorized users can access sensitive information or key resources. By implementing strong password policies, such as requiring the use of complex passwords that are long and contain a combination of uppercase letters, lowercase letters, numbers and special characters, the difficulty of illegal cracking can be significantly increased. At the same time, in complex application scenarios such as temporary networking and dynamic networks, cryptographic technology also plays an important role, which can achieve the integration and unified supervision of network security resources, ensuring that a high level of security can be maintained even in a constantly changing environment.

[0003] To further enhance security, many companies choose to use Advanced Cryptography Standard Modules (HSMs) to store and manage keys. HSMs are devices or software solutions designed specifically to perform cryptographic operations and provide physical security. By storing keys in HSMs, strict access control can be achieved to the keys, effectively preventing unauthorized personnel from obtaining these valuable assets. In addition, regular key updates are also an integral part of maintaining system security; comprehensive audit monitoring helps to identify potential risk points in a timely manner and take appropriate measures to deal with them.

[0004] However, it is worth noting that although the above methods are very effective in enhancing the security of a single account, with the development of computing power, especially supercomputer technology, it is difficult to completely resist attacks from malicious attackers by simply increasing the complexity of passwords. Therefore, how to adopt a more flexible and dynamic protection strategy from the perspective of the entire network system to increase the possibility of successful intrusion of each node has become one of the key issues that need to be solved urgently. Summary of the invention

[0005] The present invention sets up multiple cipher blocks, each of which contains a unique identifier, data content, and some metadata (such as timestamp, hash value, etc.). In order to enhance the security of the network, we define multiple cipher block mobile spaces. These spaces can be distributed in different physical locations or logical areas to increase the difficulty for attackers to obtain all cipher blocks. By dynamically moving cipher blocks between multiple mobile spaces, we can ensure that each connected part of the system is protected. Even if a mobile space is compromised, other spaces remain secure.

[0006] The technical solution proposed by the present invention is: a network security prevention method based on cryptographic technology, the method comprising:

[0007] Step 1: Obtain the network topology structure and set the network security prevention boundary;

[0008] Step 2: Construct password blocks, where each password block includes a unique identifier, data content, and metadata;

[0009] Step 3: Construct multiple mobile spaces, distribute the multiple mobile spaces at different physical locations and logical regions of the network, cover the entire network through the multiple mobile spaces, and each mobile space covers multiple network connection nodes;

[0010] Step 4: Put multiple password blocks into the mobile spaces, and the number of the password blocks is not less than the number of network nodes;

[0011] Step 5: According to the preset movement strategy, control the dynamic movement of the password blocks between the mobile spaces and control the dynamic movement of each mobile space within the network security prevention boundary;

[0012] The movement strategy is triggered based on network events and / or time, and the network events include network attack events and network communication failure events.

[0013] Preferably, the obtaining the network topology structure and setting the network security prevention boundary includes:

[0014] Use the Simple Network Management Protocol (SNMP) to obtain the IP addresses and connection statuses of target devices in the network;

[0015] Return a NetworkX graph object, and represent the network topology structure through the NetworkX graph object;

[0016] Use the API interface or configuration commands to set firewall rules for each node in the network topology structure;

[0017] Identify the central nodes of the network topology structure and visualize the central nodes and boundaries.

[0018] Preferably, the constructing the password blocks includes:

[0019] Create a block and assign a unique identifier to each block;

[0020] Add a creation timestamp to each block;

[0021] Calculate the hash value of the current block through the SHA-256 cryptographic hash function;

[0022] Verify the integrity of the block;

[0023] Verify the validity of the block;

[0024] Form multiple blocks into a linked list structure, and the password block includes multiple linked list structures.

[0025] Preferably, constructing multiple mobile spaces and distributing the multiple mobile spaces in different physical locations and logical regions of the network includes:

[0026] Setting multiple virtual environments, each virtual environment including computing resources, storage resources, and network resources;

[0027] According to the geographical information of the network or the network latency index, allocating the mobile spaces to different physical locations of the network;

[0028] Through a load balancing algorithm, allocating network requests to different mobile spaces;

[0029] Setting multiple synchronous data regions and asynchronous data regions within each mobile space, and synchronizing the data within the synchronous data regions of different mobile spaces.

[0030] Preferably, the setting multiple synchronous data regions and asynchronous data regions within each mobile space and synchronizing the data within the synchronous data regions of different mobile spaces includes:

[0031] Through a distributed transaction or a consensus algorithm, synchronizing the data within the synchronous data regions of different mobile spaces;

[0032] Storing the data that does not require strong consistency through the asynchronous data region, and returning immediately after the data that does not require strong consistency is written locally;

[0033] Through a load balancing algorithm, allocating network requests to different physical locations according to the geographical information or network latency index of each node within the network.

[0034] Preferably, the synchronizing the data within the synchronous data regions of different mobile spaces through a distributed transaction or a consensus algorithm includes:

[0035] Selecting a central node, processing write operations through the central node, and synchronizing the data to other nodes of the network;

[0036] Or, selecting multiple nodes, processing write operations through the multiple nodes, and ensuring data consistency between the multiple nodes and other unselected nodes through a conflict proximity mechanism;

[0037] Or, using a distributed transaction processing protocol to keep the operations of multiple nodes in the network consistent.

[0038] Preferably, covering the entire network through multiple mobile spaces, each mobile space covering multiple network connection nodes, includes:

[0039] Obtaining network node information and connection information of each node;

[0040] Create a set of network nodes, which includes all network node information and connection information of the network;

[0041] Create an empty list to store the final moving space through the empty list;

[0042] Select the moving space that covers the most uncovered nodes through the greedy algorithm and store it in the empty list;

[0043] Update the set of network nodes, remove the covered nodes, and stop the iteration when the set of network nodes is empty.

[0044] Preferably, according to the preset moving strategy, controlling the dynamic movement of the cipher block between each moving space and controlling the dynamic movement of each moving space within the network security prevention boundary includes:

[0045] Obtain the IP information and connection information of each node in the network topology;

[0046] Randomly generate a multi-dimensional time series one; copy the multi-dimensional time series one to generate multiple multi-dimensional time copy series one;

[0047] Encrypt the multi-dimensional time copy series one to generate a multi-dimensional time encrypted series one;

[0048] Select one or more cipher blocks according to the time points in the multi-dimensional time series one;

[0049] Randomly select nodes within the moving space and move the selected one or more cipher blocks to the selected nodes;

[0050] Copy the multi-dimensional time encrypted series one into the selected nodes to facilitate selecting the cipher blocks of the current nodes according to the time points in the multi-dimensional time encrypted series one and moving them to the next randomly selected nodes;

[0051] Repeat the above steps until all the time points in the multi-dimensional time encrypted series one are used;

[0052] Obtain the location information and size of the current moving space, and the location information of the current moving space is the geographical location information or IP information of the central node of the current moving space;

[0053] Randomly generate a multi-dimensional sequence , where , respectively represent the th switching time and the th switching position;

[0054] Randomly select a moving space;

[0055] Select a switching time point in the multi-dimensional sequence and move the moving space to the switching position at the switching time;

[0056] If the moving space exceeds the network security prevention boundary after moving to the switching position;

[0057] Calculate the area exceeding the boundary. If the area is less than the preset security area threshold, it is determined that this movement is valid; otherwise, re-select a moving space.

[0058] The present invention also provides a network security prevention system based on cryptographic technology, and the system is used to execute the network security prevention method based on cryptographic technology.

[0059] The present invention also provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the network security prevention method based on cryptographic technology.

[0060] Advantages of the present invention:

[0061] 1. In the present invention, by analyzing network devices, connection nodes, and the connection relationships between them, a topology diagram of the entire network is constructed. According to the network topology structure, one or more security regions (such as subnets) are defined, and these regions will serve as the boundaries of network security to prevent unauthorized access. A unique identifier is assigned to each password block to distinguish different password blocks. Multiple moving spaces are created in different physical locations and logical regions of the network. Ensure that each moving space can cover multiple network connection nodes to achieve comprehensive coverage of the entire network.

[0062] 2. In the present invention, according to the preset movement strategy, control the dynamic movement of password blocks between each moving space and control the dynamic movement of each moving space within the network security prevention boundary to increase the difficulty of attacker tracking. Description of the Drawings

[0063] Figure 1 It is a flowchart of a network security prevention method based on cryptographic technology of the present invention. Detailed Embodiments

[0064] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are only examples, and those skilled in the art can think of other obvious deformations. The basic principles defined in the following description can be applied to other implementation schemes, deformation schemes, improvement schemes, equivalent schemes, and other technical schemes that do not deviate from the spirit and scope of the present invention.

[0065] It is understood that the term "a" should be understood as "at least one" or "one or more". That is, in one embodiment, the number of an element can be one, while in other embodiments, the number of the element can be multiple. The term "a" should not be understood as a limitation on the quantity.

[0066] Reference Figure 1 , the technical solution provided by the present invention is: a network security prevention method based on cryptographic technology, including the following steps:

[0067] Step 1: Obtain the network topology structure and set the network security prevention boundary, including the following steps:

[0068] Use the Simple Network Management Protocol (SNMP) to obtain the IP addresses and connection status of target devices in the network; return a NetworkX graph object, and represent the network topology structure through the NetworkX graph object; use the API interface or configuration commands to set firewall rules for each node in the network topology structure; identify the central node of the network topology structure and visualize the central node and the boundary.

[0069] Step 2: Construct a cryptographic block, where the cryptographic block includes a unique identifier, data content, and metadata; among them, the data content stores actual data information, which can be encrypted data. The metadata includes information such as the creation time, last modification time, and the mobile space to which it belongs of the cryptographic block. Specifically, it includes the following steps:

[0070] Create a block and assign a unique identifier to each block; add a creation timestamp to each block;

[0071] Calculate the hash value of the current block through the SHA-256 encryption hash function;

[0072] Verify the integrity of the block; verify the validity of the block; form a linked list structure with multiple blocks, and the cryptographic block includes multiple linked list structures.

[0073] Step 3: Construct multiple mobile spaces, distribute the multiple mobile spaces at different physical locations and logical regions of the network, and cover the entire network through the multiple mobile spaces. Each mobile space covers multiple network connection nodes, including the following steps:

[0074] Set multiple virtual environments, and each of the virtual environments includes computing resources, storage resources, and network resources;

[0075] According to the geographical information of the network or the network latency index, allocate the mobile spaces to different physical locations of the network;

[0076] Through a load balancing algorithm, network requests are distributed to different mobile spaces; multiple synchronous data regions and asynchronous data regions are set within each mobile space, and the data within the synchronous data regions of different mobile spaces is synchronized. Specifically: through a distributed transaction or a consensus algorithm, the data within the synchronous data regions of different mobile spaces is synchronized;

[0077] Data that does not require strong consistency is stored through an asynchronous data region, and the data that does not require strong consistency returns immediately after being written locally;

[0078] Through a load balancing algorithm, according to the geographical information or network latency metrics of each node in the network, network requests are distributed to different physical locations.

[0079] The so-called synchronization of the data within the synchronous data regions of different mobile spaces through a distributed transaction or a consensus algorithm includes:

[0080] Select a central node, process write operations through the central node, and synchronize the data to other nodes in the network;

[0081] Alternatively, select multiple nodes, process write operations through the multiple nodes, and ensure data consistency between the multiple nodes and other unselected nodes through a conflict resolution mechanism;

[0082] Alternatively, use a distributed transaction processing protocol to keep the operations of multiple nodes in the network consistent.

[0083] Among them, the entire network is covered by multiple mobile spaces, and each mobile space covers multiple network connection nodes, including:

[0084] Obtain network node information and connection information of each node; create a network node set, and the network node set includes all network node information and connection information of the network;

[0085] Create an empty list, and store the final mobile spaces through the empty list; select the mobile space that covers the most uncovered nodes through a greedy algorithm and store it in the empty list;

[0086] Update the network node set, remove the covered nodes, and stop the iteration when the network node set is empty.

[0087] Step Four: Put multiple cipher blocks into the mobile space, and the number of the cipher blocks is not less than the number of network nodes;

[0088] Step Five: Control the dynamic movement of the password blocks among the respective movement spaces and control the dynamic movement of the respective movement spaces within the network security prevention boundary according to a preset movement strategy, where the movement strategy is triggered based on network events and / or based on time, and the network events include network attack events and network communication failure events. The steps are as follows:

[0089] Obtain the IP information and connection information of each node in the network topology;

[0090] Randomly generate a multi-dimensional time series one; copy the multi-dimensional time series one to generate multiple multi-dimensional time replication series one;

[0091] Encrypt the multi-dimensional time replication series one to generate a multi-dimensional time encryption series one;

[0092] Select one or more password blocks according to the time points in the multi-dimensional time series one;

[0093] Randomly select nodes within the movement space and move the selected one or more password blocks to the selected nodes;

[0094] Copy the multi-dimensional time encryption series one into the selected nodes to facilitate selecting the password blocks of the current nodes according to the time points in the multi-dimensional time encryption series one and moving them to the next randomly selected nodes;

[0095] Repeat the above steps until all the time points in the multi-dimensional time encryption series one are used;

[0096] Obtain the location information and size of the current movement space, where the location information of the current movement space is the geographical location information or IP information of the central node of the current movement space;

[0097] Randomly generate a multi-dimensional sequence , where , respectively represent the th switching time and the th switching location;

[0098] Randomly select a movement space;

[0099] Select a switching time point in the multi-dimensional sequence and move the movement space to the switching location at the switching time;

[0100] For example: Define a two-dimensional grid where each cell represents a possible location. Define a password block: It can be a data block or an encryption key and needs to move within the movement space. Multiple movement spaces cover the entire network; the password blocks move within the movement space according to a preset path or a randomly generated path. The movement spaces move randomly within the network security prevention boundary to change the position of the entire movement space.

[0101] Define a boundary area. The so-called boundary can be a closed area formed by the connection lines of network nodes (end nodes) located at the edge of the network. All movements of the mobile space and password blocks must be carried out within this area. Moving beyond this boundary will be regarded as an illegal operation.

[0102] If the mobile space exceeds the network security prevention boundary after moving to the handover position;

[0103] Calculate the area beyond the boundary. If the area is less than the preset security area threshold, it is determined that this movement is valid; otherwise, reselect a mobile space.

[0104] If one or more password blocks in the network node are encryption keys, password protection can be provided for this node. If one or more password blocks of each node are data blocks and encryption keys, while providing password protection for this node, it can also prevent intruders from obtaining all the data blocks from one node, because the data blocks are randomly distributed among multiple nodes, thus improving the network security protection effect.

[0105] The movement of password blocks and mobile spaces can also be triggered by events. For example, if the password blocks of a node are illegally obtained or cracked, one or more password blocks in a mobile space move to the corresponding node to protect the connection of this node.

[0106] Similarly, if multiple nodes in a mobile area are damaged, the computing resources and network resources in this mobile space are transferred to another mobile space. Through the movement of the mobile space, the destroyer cannot utilize the computing resources and network resources in this mobile space, and thus cannot use the network nodes in the mobile space to attack other mobile spaces in the network. At the same time, when the mobile space moves, the data in the synchronized data area is copied to the new location, and the data at the original location is deleted; the consistency of the data during the movement can be ensured through a lock mechanism or a transaction, so that the attacker cannot obtain the data in the synchronized data area; by selecting the synchronized data movement, the amount of data movement is reduced, and the data movement speed can be increased.

[0107] The present invention also provides a network security prevention system based on cryptographic technology, and the system is used to execute the above-mentioned network security prevention method based on cryptographic technology.

[0108] The present invention also provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the above-mentioned network security prevention method based on cryptographic technology.

[0109] Embodiments disclosed in the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. Embodiments disclosed in the present invention include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part, and / or installed from a removable medium. When the computer program is executed by a central processing unit (CPU), the above functions defined in the methods of the present application are performed. It should be noted that the computer-readable medium in the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can, for example, but not be limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wire segments, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. And in the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program codes. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program codes contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: a wireless segment, a wire segment, an optical cable, RF, etc., or any suitable combination of the above.

[0110] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code, which contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0111] Those skilled in the art should understand that the embodiments of the present invention described above and shown in the accompanying drawings are only examples and do not limit the present invention. The objectives of the present invention have been fully and effectively achieved. The functions and structural principles of the present invention have been demonstrated and explained in the embodiments. Without departing from the said principles, any changes or modifications can be made to the embodiments of the present invention.

Claims

1. A network security prevention method based on cryptographic technology, characterized in that, The method includes: Step 1: Obtain the network topology structure and set the network security prevention boundary; Step 2: Construct a password block, where the password block includes a unique identifier, data content, and metadata; Step 3: Construct multiple mobile spaces, distribute the multiple mobile spaces at different physical locations and logical regions of the network, cover the entire network through the multiple mobile spaces, and each mobile space covers multiple network connection nodes; Step 4: Put multiple password blocks into the mobile spaces, and the number of the password blocks is not less than the number of network nodes; Step 5: According to the preset movement strategy, control the dynamic movement of the password blocks between the mobile spaces and control the dynamic movement of each mobile space within the network security prevention boundary; including: Obtain the IP information and connection information of each node in the network topology structure; Randomly generate a multi-dimensional time series one; copy the multi-dimensional time series one to generate multiple multi-dimensional time replication series one; Encrypt the multi-dimensional time replication series one to generate a multi-dimensional time encryption series one; According to the time points in the multi-dimensional time series one, select one or more password blocks; Randomly select nodes within the mobile space and move the selected one or more password blocks to the selected nodes; Copy the multi-dimensional time encryption series one into the selected nodes to facilitate selecting the password blocks of the current nodes according to the time points in the multi-dimensional time encryption series one and moving them to the next randomly selected nodes; Repeat the above steps until all the time points in the multi-dimensional time encryption series one are used; Obtain the location information and size of the current mobile space, and the location information of the current mobile space is the geographical location information or IP information of the central node of the current mobile space; Randomly generate a multi-dimensional sequence , where , respectively represent the th switching time and the th switching position; It also includes: randomly select a mobile space; Select a switching time point in the multi-dimensional sequence and move the mobile space to the switching position at the switching time; If the mobile space exceeds the network security prevention boundary after moving to the switching position; Calculate the exceeded area. If the area is less than the preset security area threshold, it is determined that this movement is valid; otherwise, reselect a mobile space; The movement strategy is triggered based on network events and / or time, and the network events include network attack events and network communication failure events.

2. The network security prevention method based on cryptographic technology according to claim 1, wherein, The obtaining of the network topology structure and setting the network security prevention boundary includes: Use the Simple Network Management Protocol SNMP to obtain the IP addresses and connection statuses of target devices in the network; Return a NetworkX graph object and represent the network topology structure through the NetworkX graph object; Use the API interface or configuration commands to set firewall rules for each node in the network topology structure; Identify the central node of the network topology structure and visualize the central node and the boundary.

3. A network security prevention method based on cryptographic technology according to claim 2, characterized in that The constructing of the password block includes: Create a block and assign a unique identifier to each block; Add a creation timestamp to each block; Calculate the hash value of the current block through the SHA-256 encryption hash function; Verify the integrity of the block; Verify the validity of the block; Form a linked list structure with multiple blocks, and the password block includes multiple linked list structures.

4. A network security prevention method based on cryptographic technology according to claim 3, characterized in that, Construct multiple mobile spaces and distribute them in different physical locations and logical regions of the network, including: Set up multiple virtual environments, each of which includes computing resources, storage resources, and network resources; According to the geographical information of the network or network latency metrics, allocate mobile spaces to different physical locations of the network; Through the load balancing algorithm, allocate network requests to different mobile spaces; Set up multiple synchronous data regions and asynchronous data regions within each mobile space, and synchronize the data within the synchronous data regions of different mobile spaces.

5. A network security prevention method based on cryptographic technology according to claim 4, characterized in that, The step of setting up multiple synchronous data regions and asynchronous data regions within each mobile space and synchronizing the data within the synchronous data regions of different mobile spaces includes: Synchronize the data within the synchronous data regions of different mobile spaces through distributed transactions or consensus algorithms; Store data that does not require strong consistency through the asynchronous data region, and the data that does not require strong consistency returns immediately after being written locally; Through the load balancing algorithm, allocate network requests to different physical locations according to the geographical information or network latency metrics of each node in the network.

6. A network security prevention method based on cryptographic technology according to claim 5, characterized in that The step of synchronizing the data within the synchronous data regions of different mobile spaces through distributed transactions or consensus algorithms includes: Select a central node, process write operations through the central node, and synchronize the data to other nodes in the network; Alternatively, select multiple nodes, process write operations through the multiple nodes, and ensure data consistency between the multiple nodes and other unselected nodes through a conflict resolution mechanism; Alternatively, use a distributed transaction processing protocol to keep the operations of multiple nodes in the network consistent.

7. A network security prevention method based on cryptographic technology according to claim 6, characterized in that, The step of covering the entire network through multiple mobile spaces, where each mobile space covers multiple network connection nodes, includes: Obtain network node information and connection information for each node; Create a network node set, which includes all network node information and connection information of the network; Create an empty list and store the final mobile spaces through the empty list; Select a mobile space that covers the most uncovered nodes through the greedy algorithm and store it in the empty list; Update the network node set, remove the covered nodes, and stop the iteration when the network node set is empty.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement a network security prevention method according to any one of claims 1-7 above.

Citation Information

Patent Citations

  • Active protection system for wireless self-organizing network

    CN101355416A

  • Cross-network security situation awareness and early warning notification system

    CN118316741A